Agent skill

Dt Sec Semantic Mapping

by Dynatrace in Dynatrace/dynatrace-for-ai

Suggest and validate semantic dictionary (SD) mappings for new security integrations using vendor API samples or live events.

Apache-2.0Auto-check passed

Install Dt Sec Semantic Mapping

skills CLI
$ npx skills add Dynatrace/dynatrace-for-ai --skill dt-sec-semantic-mapping -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Dynatrace/dynatrace-for-ai dt-sec-semantic-mapping --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Dynatrace/dynatrace-for-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dt-sec-semantic-mapping .claude/skills/dt-sec-semantic-mapping && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dt-sec-semantic-mapping
GitHub stars
162
Token cost
~1.5k tokens
SKILL.md length
584 words
Files
21 (incl. references)
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Suggest and validate semantic dictionary (SD) mappings for new security integrations using vendor API samples or live events.

  • : mapping a new security vendor data to Dynatrace SD
  • SKILL.md covers Purpose, Semantic Dictionary, Required Inputs and Baseline Sources…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Checking required fields

What it does

Dt Sec Semantic Mapping is an agent skill from Dynatrace/dynatrace-for-ai. Suggest and validate semantic dictionary (SD) mappings for new security integrations using vendor API samples or live events. Use when: mapping a new security vendor data to Dynatrace SD; checking required fields; validating namespaces; highlighting discrepancies vs the semantic dictionary; proposing mapping improvements; running runtime validation against live tenant data.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 22 other files, including reference files (for example `references/intake-and-constraints.md`, `references/mapping-workflow.md` and `references/runtime-validation.md`).

The repository describes itself as: Skills, prompts, and instructions for building AI agents on top of Dynatrace production context. The licence is Apache-2.0.

When your agent uses it

  • : mapping a new security vendor data to Dynatrace SD
  • Checking required fields
  • Validating namespaces
  • Highlighting discrepancies vs the semantic dictionary

Example prompts

  • “/dt-sec-semantic-mapping”

What it can do on your machine

Read from SKILL.md and the folder at commit 4f9aa71. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.dynatrace.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dt Sec Semantic Mapping loads about 1.5k tokens when it runs, and up to ~44k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 584 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~100
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~44k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Dynatrace/dynatrace-for-ai at commit 4f9aa71, republished under its Apache-2.0 licence (© Dynatrace). 584 words, ~1,470 tokens.

Download SKILL.mdSave it as .claude/skills/dt-sec-semantic-mapping/SKILL.md (or your agent's skills folder). This skill also uses 20 other files; get the full folder from GitHub.
name
dt-sec-semantic-mapping
description
Suggest and validate semantic dictionary (SD) mappings for new security integrations using vendor API samples or live events. Use when: mapping a new security vendor data to Dynatrace SD; checking required fields; validating namespaces; highlighting discrepancies vs the semantic dictionary; proposing mapping improvements; running runtime validation against live tenant data.
license
Apache-2.0

dt-sec-semantic-mapping

Build and validate semantic-dictionary-aligned mappings for new security integrations.

Purpose

Use this skill when a user wants to:

  • Suggest a mapping from vendor API output to Dynatrace security.events fields (Workflow A).
  • Validate an existing mapping for completeness and quality against:
    • Local baseline samples and semantic dictionary (Workflow B1 — static, offline validation), or
    • Live tenant data via live tenant access (Workflow B2 — runtime validation)
  • Highlight discrepancies vs. the Semantic Dictionary and local references.
  • Get actionable mapping improvements.

Semantic Dictionary

The Semantic Dictionary (SD) defines the canonical field set for security.events. See references/semantic-reference.md for the canonical reference: local-vs-live sources, queryable Grail tables, when-to-query decision matrix, and the authority rule (live SD wins on disagreement).

Required Inputs

Always run the intake checklist in references/intake-and-constraints.md before generating or validating a mapping. If inputs are incomplete, continue with a partial draft but explicitly list missing evidence and confidence limits.

Baseline Sources (self-contained)

All baseline material lives inside this skill:

  • samples/ — real integration payloads covering all finding types and providers. Consulted as a fallback when primary references (SD, data-model-notes, known-discrepancies, validation-rules, object-type-expectations) leave a specific question unresolved — not as a routine step on every workflow run.
  • references/semantic-reference.md — SD reference, field taxonomy, event types, provider taxonomy, and entity scoping
  • references/validation-policy-and-reporting.md — validation rules, acceptable discrepancies, and report templates
  • references/intake-and-constraints.md — intake checklist, output contract, object.type expectations, and OpenPipeline constraints

Event-Type Coverage Requirements

The mapping MUST address the correct set of event.type values per finding class. Detection integrations are push-based and do not use scan cycles — never require scan events for detection.

See validation-policy-and-reporting.md § Event-Type Coverage for the full table, severity rules, and the alternative-classification path when a detection-class mapping incorrectly emits *_SCAN events.

Workflows

This skill operates in three modes. Detect the mode from context:

ModeInputProcedural source
Workflow A — Suggest a new mappingRaw vendor API payloads onlyreferences/mapping-workflow.md § Workflow A (Phase 1 mapping table → user approval → Phase 2 sample JSON)
Workflow B1 — Static validationExisting mapping + vendor API samplesreferences/mapping-workflow.md § Workflow B — classify input mode (final ingested / theoretical), apply rules, produce diff-highlighted table
Workflow B2 — Runtime validationExisting mapping + live tenant accessreferences/runtime-validation.md — load the security (AppSec) events supporting skill first (REQUIRED Step 0), then run the query pack, produce a Validation Summary table

All workflows follow the output contracts in references/intake-and-constraints.md and the report templates in references/validation-policy-and-reporting.md. Validation rules (event-type coverage, required fields, scan references, namespace requirements, value/type checks, vendor-namespace duplication) live in references/validation-policy-and-reporting.md.

Show full SKILL.md (184 more words)Show less

Acceptable Discrepancy Policy

See references/validation-policy-and-reporting.md for the canonical list of acceptable SD deviations and vendor-namespace patterns. Do NOT raise critical/major issues for fields on that list. Genuinely unknown fields (not in local refs AND not in the live SD — see references/semantic-reference.md) must be questioned per references/validation-policy-and-reporting.md.

Scope

This skill covers:

  • Mapping suggestion and refinement (Workflow A).
  • Static validation against local baseline examples and semantic dictionary (Workflow B1).
  • Runtime validation via live tenant access against live tenant data (Workflow B2).
  • Semantic-dictionary conformance checks.
  • Gap analysis and improvement recommendations.

This skill does not cover:

  • Live ingestion pipeline deployment.
  • Runtime DQL performance benchmarking.
  • Tenant-side ingestion troubleshooting.

References

  • references/semantic-reference.md — SD reference plus data-model notes: local sources, live (queryable) sources, DQL patterns, when-to-query decision matrix, authority rule, field taxonomy
  • A skill covering full SD access patterns and Grail-table documentation — for DQL query patterns against security.events and Grail tables
  • Semantic Dictionary (public docs)
  • references/intake-and-constraints.md — intake checklist, output contract, OpenPipeline constraints, and object.type namespace expectations
  • references/mapping-workflow.md — how to build and refine a mapping candidate
  • references/validation-policy-and-reporting.md — full validation rule set, known discrepancies, and discrepancy report templates
  • references/runtime-validation.md — optional real-environment query validation pack

© Dynatrace, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 20 other files (references) in skills/dt-sec-semantic-mapping of Dynatrace/dynatrace-for-ai.

  • SKILL.md
  • references/intake-and-constraints.md
  • references/mapping-workflow.md
  • references/runtime-validation.md
  • references/semantic-reference.md
  • references/validation-policy-and-reporting.md
  • samples/dynatrace-compliance-scans.json
  • samples/dynatrace-compliance.json
  • samples/dynatrace-detections-automated.json
  • samples/dynatrace-detections-rap.json
  • samples/dynatrace-vulnerabilities-change-events.json
  • samples/dynatrace-vulnerabilities-findings.json
  • samples/dynatrace-vulnerabilities-scans.json
  • samples/dynatrace-vulnerabilities-state-reports.json
  • samples/external-compliance.json
  • samples/external-detections.json
  • samples/external-threat-reports.json
  • samples/external-vulnerabilities-code-artifact.json
  • samples/external-vulnerabilities-container-image.json
  • … and 2 more

Open the folder on GitHubat commit 4f9aa71

Compare with similar skills

Dt Sec Semantic Mapping next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dt Sec Semantic Mapping compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dt Sec Semantic Mapping this skillDynatrace/dynatrace-for-ai162—~1.5kAutomated safety check: PassApache-2.0
Token Mapnexu-io/open-design100k—~1.4kAutomated safety check: PassApache-2.0
Maps Geographyasgeirtj/system_prompts_leaks69k—~717Automated safety check: PassCC0-1.0
Suggestion Boxpaperclipai/paperclip99k—~1.3kAutomated safety check: PassMIT
Feature Maponyx-dot-app/onyx32k—~459Automated safety check: PassCustom licence
Semantic Liststhedaviddias/Front-End-Checklist74k—~504Automated safety check: PassMIT

Similar skills

  • Token Map

    nexu-io/open-design

    Map an extracted Figma / source-code token bag onto the active OD design system, producing a deterministic mapping the generate stage can consume.

    100k GitHub stars~1.4k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Maps Geography

    asgeirtj/system_prompts_leaks

    Accurate maps from real geo data — use for any map, or whenever geography would make a good graphic for a deliverable

    69k GitHub stars~717 tokensUpdated yesterday
    Auto-check passed
  • Suggestion Box

    paperclipai/paperclip

    Quietly suggest a concrete improvement after observing material, generalizable friction in agent work.

    99k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Feature Map

    onyx-dot-app/onyx

    Use the Onyx feature map (.agents/feature-map/) to learn what a product surface does, the code behind it, and what a change can break.

    32k GitHub stars~459 tokensUpdated today
    Auto-check passed
  • Semantic Lists

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Use semantic list elements.

    74k GitHub stars~504 tokensUpdated 3 days ago
    Frontend & DesignAuto-check passed
  • Source Maps

    thedaviddias/Front-End-Checklist

    A skill your agent uses when auditing slow page loads, heavy assets, or rendering delays related to Provide source maps for production debugging.

    74k GitHub stars~445 tokensUpdated 3 days ago
    DevelopmentAuto-check passed

More from Dynatrace/dynatrace-for-ai

All 33 skills in this repo
  • Dt Obs Analytics

    Dynatrace/dynatrace-for-ai

    Analyze dashboards and notebooks using Davis analyzers — anomaly detection, novelty scoring, and correlation.

    162 GitHub stars~3.9k tokensUpdated 8 days ago
    Auto-check passed
  • Dt Setup iOS

    Dynatrace/dynatrace-for-ai

    Set up the Dynatrace iOS SDK (OneAgent) in an iOS project using Swift Package Manager.

    162 GitHub stars~3.3k tokensUpdated 8 days ago
    Auto-check passed
  • Dt Alerting

    Dynatrace/dynatrace-for-ai

    End-to-end Dynatrace alerting lifecycle — anomaly detector setup and model selection (static threshold, adaptive baseline, seasonal baseline), alert event storage in Grail, problem grouping and…

    162 GitHub stars~3.3k tokensUpdated 8 days ago
    Auto-check passed
  • Dt Obs AWS

    Dynatrace/dynatrace-for-ai

    AWS cloud resource monitoring including EC2, RDS, Lambda, ECS/EKS, VPC networking, load balancers, S3, DynamoDB, SQS/SNS, and cost optimization.

    162 GitHub stars~4.2k tokensUpdated 8 days ago
    Auto-check passed
  • Dt Obs Ext Monitors

    Dynatrace/dynatrace-for-ai

    3rd-party test and monitor result ingestion into Dynatrace Grail via the platform events ingest API (platform/ingest/custom/events/).

    162 GitHub stars~1.5k tokensUpdated 8 days ago
    Auto-check passed
  • Dt Obs Problems

    Dynatrace/dynatrace-for-ai

    DAVIS problem analysis including root cause identification, impact assessment, and correlation with other telemetry.

    162 GitHub stars~4.6k tokensUpdated 8 days ago
    Auto-check passed

Questions about Dt Sec Semantic Mapping

What does Dt Sec Semantic Mapping do?

Suggest and validate semantic dictionary (SD) mappings for new security integrations using vendor API samples or live events. Dt Sec Semantic Mapping is an agent skill from Dynatrace/dynatrace-for-ai. Suggest and validate semantic dictionary (SD) mappings for new security integrations using vendor API samples or live events.

When should I use Dt Sec Semantic Mapping?

Dt Sec Semantic Mapping fits situations like: : mapping a new security vendor data to Dynatrace SD; checking required fields; validating namespaces; highlighting discrepancies vs the semantic dictionary.

How do I install Dt Sec Semantic Mapping in Claude Code?

Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-sec-semantic-mapping -a claude-code`. Or copy the skill folder (skills/dt-sec-semantic-mapping in Dynatrace/dynatrace-for-ai) into .claude/skills/dt-sec-semantic-mapping in your project. Claude Code loads it when a task matches its description.

How do I install Dt Sec Semantic Mapping in Codex?

Run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-sec-semantic-mapping -a codex`. Or copy the skill folder (skills/dt-sec-semantic-mapping in Dynatrace/dynatrace-for-ai) into .agents/skills/dt-sec-semantic-mapping in your project. Codex loads it when a task matches its description.

Can I use Dt Sec Semantic Mapping in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Dynatrace/dynatrace-for-ai --skill dt-sec-semantic-mapping -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dt-sec-semantic-mapping, .gemini/skills/dt-sec-semantic-mapping, .github/skills/dt-sec-semantic-mapping and .opencode/skills/dt-sec-semantic-mapping in your project.

What does Dt Sec Semantic Mapping need to run?

SKILL.md names no scripts, command-line tools or credentials: Dt Sec Semantic Mapping is instructions for the agent only.

Does Dt Sec Semantic Mapping access the network?

SKILL.md names 1 domain. As links in the text: docs.dynatrace.com. This is read from the text; nothing was executed.

Is Dt Sec Semantic Mapping safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dt Sec Semantic Mapping use?

Dt Sec Semantic Mapping is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dt Sec Semantic Mapping use?

About 1.5k tokens (SKILL.md is roughly 5.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 43k tokens, read only when the agent opens those files.

What are the alternatives to Dt Sec Semantic Mapping?

Skills that share tags, products or a category with Dt Sec Semantic Mapping: Token Map (nexu-io/open-design, 100k stars), Maps Geography (asgeirtj/system_prompts_leaks, 69k stars), Suggestion Box (paperclipai/paperclip, 99k stars) and Feature Map (onyx-dot-app/onyx, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dt Sec Semantic Mapping?

Dynatrace (a GitHub organization) maintains it in Dynatrace/dynatrace-for-ai, which has 162 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.

Source: Dynatrace/dynatrace-for-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.